PT-2011-5045 · Pixie · Pixie Cms
Piranha
·
Published
2011-12-08
·
Updated
2021-03-29
·
CVE-2011-4710
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pixie CMS versions 1.01 through 1.04
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
pixie user parameter and the Referer HTTP header in a request to the default URI.Recommendations
For Pixie CMS versions 1.01 through 1.04, consider restricting access to the default URI and avoid using the
pixie user parameter until a fix is available. As a temporary workaround, restrict the Referer HTTP header to minimize the risk of exploitation.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pixie Cms